Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b8d53881 by security tracker role at 2025-11-07T20:13:30+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,143 @@
+CVE-2025-9458 (A maliciously crafted PRT file, when parsed through certain 
Autodesk p ...)
+       TODO: check
+CVE-2025-7719 (Improper Limitation of a Pathname to a Restricted Directory 
('Path Tra ...)
+       TODO: check
+CVE-2025-64432 (KubeVirt is a virtual machine management add-on for 
Kubernetes. Versio ...)
+       TODO: check
+CVE-2025-64431 (Zitadel is an open source identity management platform. 
Versions 4.0.0 ...)
+       TODO: check
+CVE-2025-64430 (Parse Server is an open source backend that can be deployed to 
any inf ...)
+       TODO: check
+CVE-2025-64347 (Apollo Router Core is a configurable Rust graph router written 
to run  ...)
+       TODO: check
+CVE-2025-63785 (A DOM-based Cross-Site Scripting (XSS) vulnerability exists in 
the tex ...)
+       TODO: check
+CVE-2025-63784 (An Open Redirect vulnerability exists in the OAuth callback 
handler in ...)
+       TODO: check
+CVE-2025-63783 (A Broken Object Level Authorization (BOLA) vulnerability was 
discovere ...)
+       TODO: check
+CVE-2025-63718 (A SQL injection vulnerability exists in the SourceCodester 
PQMS (Patie ...)
+       TODO: check
+CVE-2025-63717 (The change password functionality at 
/pet_grooming/admin/change_pass.p ...)
+       TODO: check
+CVE-2025-63716 (The SourceCodester Leads Manager Tool v1.0 is vulnerable to 
Cross-Site ...)
+       TODO: check
+CVE-2025-63714 (Cross-Site Scripting (XSS) vulnerability in SourceCodester 
User Accoun ...)
+       TODO: check
+CVE-2025-63713 (Cross-Site Scripting (XSS) vulnerability in SourceCodester 
"MatchMaste ...)
+       TODO: check
+CVE-2025-63691 (In pig-mesh In Pig version 3.8.2 and below, within the Token 
Managemen ...)
+       TODO: check
+CVE-2025-63690 (In pig-mesh Pig versions 3.8.2 and below, when setting up 
scheduled ta ...)
+       TODO: check
+CVE-2025-63689 (Multiple SQL injection vulnerabilitites in ycf1998 money-pos 
system be ...)
+       TODO: check
+CVE-2025-63687 (An issue was discovered in rymcu forest thru commit f782e85 
(2025-09-0 ...)
+       TODO: check
+CVE-2025-63686 (There is an arbitrary file download vulnerability in GuoMinJim 
PersonM ...)
+       TODO: check
+CVE-2025-63640 (Sourcecodester Medicine Reminder App v1.0 is vulnerable to 
Cross-Site  ...)
+       TODO: check
+CVE-2025-63639 (The chat feature in the application Sourcecodester FAQ Bot 
with AI Ass ...)
+       TODO: check
+CVE-2025-63638 (Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to 
Cross-S ...)
+       TODO: check
+CVE-2025-61261 (A reflected cross-site scripting (XSS) vulnerability in 
CKeditor v46.1 ...)
+       TODO: check
+CVE-2025-58469 (A cross-site request forgery (CSRF) vulnerability has been 
reported to ...)
+       TODO: check
+CVE-2025-58465 (A cross-site scripting (XSS) vulnerability has been reported 
to affect ...)
+       TODO: check
+CVE-2025-58464 (A relative path traversal vulnerability has been reported to 
affect Qu ...)
+       TODO: check
+CVE-2025-58463 (A relative path traversal vulnerability has been reported to 
affect Do ...)
+       TODO: check
+CVE-2025-57712 (A path traversal vulnerability has been reported to affect 
Qsync Centr ...)
+       TODO: check
+CVE-2025-57706 (A cross-site scripting (XSS) vulnerability has been reported 
to affect ...)
+       TODO: check
+CVE-2025-57698 (AstrBot Project v3.5.22 contains a directory traversal 
vulnerability.  ...)
+       TODO: check
+CVE-2025-57697 (AstrBot Project v3.5.22 has an arbitrary file read 
vulnerability in fu ...)
+       TODO: check
+CVE-2025-54168 (A cross-site scripting (XSS) vulnerability has been reported 
to affect ...)
+       TODO: check
+CVE-2025-54167 (A cross-site scripting (XSS) vulnerability has been reported 
to affect ...)
+       TODO: check
+CVE-2025-53413 (An allocation of resources without limits or throttling 
vulnerability  ...)
+       TODO: check
+CVE-2025-53412 (A NULL pointer dereference vulnerability has been reported to 
affect F ...)
+       TODO: check
+CVE-2025-53411 (An allocation of resources without limits or throttling 
vulnerability  ...)
+       TODO: check
+CVE-2025-53410 (An allocation of resources without limits or throttling 
vulnerability  ...)
+       TODO: check
+CVE-2025-53409 (An allocation of resources without limits or throttling 
vulnerability  ...)
+       TODO: check
+CVE-2025-53408 (A NULL pointer dereference vulnerability has been reported to 
affect F ...)
+       TODO: check
+CVE-2025-52865 (A NULL pointer dereference vulnerability has been reported to 
affect F ...)
+       TODO: check
+CVE-2025-52425 (An SQL injection vulnerability has been reported to affect 
QuMagie. A  ...)
+       TODO: check
+CVE-2025-47207 (A NULL pointer dereference vulnerability has been reported to 
affect s ...)
+       TODO: check
+CVE-2025-46413 (Use of password hash with insufficient computational effort 
issue exis ...)
+       TODO: check
+CVE-2025-3222 (Improper Authentication vulnerability in GE Vernova Smallworld 
on Wind ...)
+       TODO: check
+CVE-2025-36186 (IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows 
(includes Db ...)
+       TODO: check
+CVE-2025-36185 (IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows 
(includes Db ...)
+       TODO: check
+CVE-2025-36136 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for 
Linux, UN ...)
+       TODO: check
+CVE-2025-36135 (IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 
through ...)
+       TODO: check
+CVE-2025-36131 (IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 
12.1.0 thr ...)
+       TODO: check
+CVE-2025-36008 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for 
Linux, UN ...)
+       TODO: check
+CVE-2025-36006 (IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 
11.5.0 throug ...)
+       TODO: check
+CVE-2025-34299 (Monsta FTP versions 2.11 and earlier contain a vulnerability 
that allo ...)
+       TODO: check
+CVE-2025-33012 (IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 
11.5.0 throug ...)
+       TODO: check
+CVE-2025-2534 (IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 
12.1.0 thr ...)
+       TODO: check
+CVE-2025-12890 (Improper handling of  malformed Connection Request with the 
interval s ...)
+       TODO: check
+CVE-2025-12873 (A security flaw has been discovered in Campcodes School File 
Managemen ...)
+       TODO: check
+CVE-2025-12862 (A vulnerability was identified in projectworlds Online Notes 
Sharing P ...)
+       TODO: check
+CVE-2025-12861 (A vulnerability was determined in DedeBIZ up to 6.3.2. 
Affected by thi ...)
+       TODO: check
+CVE-2025-12860 (A vulnerability was found in DedeBIZ up to 6.3.2. Affected is 
an unkno ...)
+       TODO: check
+CVE-2025-12859 (A vulnerability has been found in DedeBIZ up to 6.3.2. This 
impacts an ...)
+       TODO: check
+CVE-2025-12858
+       REJECTED
+CVE-2025-12857 (A security vulnerability has been detected in code-projects 
Responsive ...)
+       TODO: check
+CVE-2025-12856 (A weakness has been identified in code-projects Responsive 
Hotel Site  ...)
+       TODO: check
+CVE-2025-12855 (A security flaw has been discovered in code-projects 
Responsive Hotel  ...)
+       TODO: check
+CVE-2025-12854 (A vulnerability was identified in newbee-mall-plus up to 
2.4.1. This v ...)
+       TODO: check
+CVE-2025-12853 (A vulnerability was determined in SourceCodester Best House 
Rental Man ...)
+       TODO: check
+CVE-2025-12829 (An uninitialized stack read issue exists in Amazon Ion-C 
versions <v1. ...)
+       TODO: check
+CVE-2025-10968 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
+       TODO: check
+CVE-2025-10870 (SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows 
an atta ...)
+       TODO: check
+CVE-2024-47118 (IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 
11.5.0 throug ...)
+       TODO: check
 CVE-2025-64346 (archives is a Go library for extracting archives (tar, zip, 
etc.). Ver ...)
        NOT-FOR-US: jaredallard/archives Go library
 CVE-2025-64343 ((conda) Constructor is a tool that enables users to create 
installers  ...)
@@ -435,7 +575,7 @@ CVE-2025-22288 (Path Traversal: '.../...//' vulnerability 
in WPMU DEV - Your All
        NOT-FOR-US: WordPress plugin or theme
 CVE-2025-12815 (An ownership verification issue in the Virtual Desktop preview 
page in ...)
        NOT-FOR-US: Amazon
-CVE-2025-12808 (Improper access control in Devolutions Server 2025.3.5.0 and 
earlier a ...)
+CVE-2025-12808 (Improper access control in Devolutions allows a View-only 
userto retri ...)
        NOT-FOR-US: Devolutions
 CVE-2025-12556 (An argument injection vulnerability exists in the affected 
product tha ...)
        NOT-FOR-US: IDIS
@@ -529,18 +669,23 @@ CVE-2025-10683 (The Easy Email Subscription plugin for 
WordPress is vulnerable t
 CVE-2025-10259 (Improper Validation of Specified Quantity in Input 
vulnerability in TC ...)
        NOT-FOR-US: Mitsubishi
 CVE-2025-12729
+       {DSA-6050-1}
        - chromium 142.0.7444.134-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2025-12728
+       {DSA-6050-1}
        - chromium 142.0.7444.134-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2025-12727
+       {DSA-6050-1}
        - chromium 142.0.7444.134-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2025-12726
+       {DSA-6050-1}
        - chromium 142.0.7444.134-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2025-12725
+       {DSA-6050-1}
        - chromium 142.0.7444.134-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2025-64459 (An issue was discovered in 5.1 before 5.1.14, 4.2 before 
4.2.26, and 5 ...)
@@ -1775,9 +1920,11 @@ CVE-2025-34271 (Nagios Log Server versions prior 
to2024R2.0.2 contain a vulnerab
        NOT-FOR-US: Nagios Log Server
 CVE-2025-34270 (Nagios Log Server versions prior to 2024R2.0.2 contain a 
vulnerability ...)
        NOT-FOR-US: Nagios Log Server
-CVE-2025-34269 (Nagios Fusion versions prior to R2.1 contain a vulnerability 
due to th ...)
+CVE-2025-34269
+       REJECTED
        NOT-FOR-US: Nagios Fusion
-CVE-2025-34249 (Nagios Fusion versions prior to 2024R2.1contain a brute-force 
bypass i ...)
+CVE-2025-34249
+       REJECTED
        NOT-FOR-US: Nagios Fusion
 CVE-2025-34135 (Nagios XI versions prior to2024R1.4.2configure some systemd 
unit files ...)
        NOT-FOR-US: Nagios XI
@@ -6904,7 +7051,7 @@ CVE-2025-9640 (A flaw was found in Samba, in the 
vfs_streams_xattr module, where
        [bookworm] - samba <no-dsa> (Minor issue; will be fixed via point 
release)
        NOTE: https://www.samba.org/samba/security/CVE-2025-9640.html
        NOTE: https://bugzilla.samba.org/show_bug.cgi?id=15885
-CVE-2025-10230 [Command injection via WINS server hook script]
+CVE-2025-10230 (A flaw was found in Samba, in the front-end WINS hook 
handling: NetBIO ...)
        - samba 2:4.23.2+dfsg-1
        [trixie] - samba <no-dsa> (Minor issue; will be fixed via point release)
        [bookworm] - samba <no-dsa> (Minor issue; will be fixed via point 
release)
@@ -22675,7 +22822,7 @@ CVE-2025-58371 (Roo Code is an AI-powered autonomous 
coding agent that lives in
        NOT-FOR-US: Roo Code
 CVE-2025-58370 (Roo Code is an AI-powered autonomous coding agent that lives 
in users' ...)
        NOT-FOR-US: Roo Code
-CVE-2025-58369 (fs2 is a compositional, streaming I/O library for Scala. 
Versions 3.12 ...)
+CVE-2025-58369 (fs2 is a compositional, streaming I/O library for Scala. 
Versions up t ...)
        NOT-FOR-US: fs2 compositional, streaming I/O library for Scala
 CVE-2025-58367 (DeepDiff is a project focused on Deep Difference and search of 
any Pyt ...)
        NOT-FOR-US: DeepDiff
@@ -37932,7 +38079,7 @@ CVE-2025-53644 (OpenCV is an Open Source Computer 
Vision Library. Versions 4.10.
        NOTE: completely via Files-Excluded.
 CVE-2024-6234
        NOT-FOR-US: Ansible Automation Platform
-CVE-2025-7700 [NULL Pointer Dereference in FFmpeg ALS Decoder 
(libavcodec/alsdec.c)]
+CVE-2025-7700 (A flaw was found in FFmpeg\u2019s ALS audio decoder, where it 
does not ...)
        {DSA-6007-1 DSA-5985-1}
        - ffmpeg 7:7.1.2-1
        [bullseye] - ffmpeg <postponed> (Minor issue, wait until it's fixed in 
the 4.3 branch)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b8d5388128037493dbe17fbbf2166375adab2831

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b8d5388128037493dbe17fbbf2166375adab2831
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to